In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
References
Configurations
History
21 Nov 2024, 09:23
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | () https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef - Patch | |
References | () https://web.mit.edu/kerberos/www/advisories/ - Vendor Advisory |
18 Sep 2024, 12:39
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
|
First Time |
Debian debian Linux
Debian |
27 Aug 2024, 17:47
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other | |
References | () https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef - Patch | |
References | () https://web.mit.edu/kerberos/www/advisories/ - Vendor Advisory | |
CPE | cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
First Time |
Mit
Mit kerberos 5 |
01 Jul 2024, 12:37
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
28 Jun 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-28 23:15
Updated : 2024-11-21 09:23
NVD link : CVE-2024-37371
Mitre link : CVE-2024-37371
CVE.ORG link : CVE-2024-37371
JSON object : View
Products Affected
debian
- debian_linux
mit
- kerberos_5
CWE